CHINA Law and Practice Contributed by: Kate Yin, Sherman Deng, Yanjun Zhuang and Daniel Wang, Fangda Partners
2.4 State Responsibilities and Obligations The CSL and DSL comprehensively prescribe state obligations. Under the CSL, the state is responsible for formu - lating the cybersecurity strategy, clarifying basic requirements and major objectives, and establishing a cybersecurity protection system to enhance pro - tection capabilities. The state shall adopt measures to monitor, defend against and handle cybersecurity risks and threats, with particular focus on safeguard - ing CIIs. Under the DSL, the state shall establish a data securi - ty governance system and integrate data security into the national security outlook. Specifically, it stipulates the establishment of a data classification and grading protection system, as well as a data security review system to conduct national security reviews of data processing activities that affect national security. Regarding threat intelligence sharing, the CSL man - dates state supervision and administration of net - work information security, and the establishment of a cybersecurity monitoring, early warning and informa - tion notification system. It also supports co-operation between network operators and requires the stand - ardised release of cybersecurity-related information. Under the DSL, the state shall establish a data secu - rity emergency response process. As for public-private co-operation, the CSL stipulates that the state shall support enterprises and educa - tional institutions in conducting cybersecurity-related education and training, cultivate talent, and encour - age enterprises to offer cybersecurity certification, testing and risk assessment services as part of pro - cedural safe harbours. The DSL encourages relevant entities to formulate data security codes of conduct and group standards to guide their members in fulfill - ing data protection obligations.
tion of cybersecurity incident handling through the original reporting channel. With respect to reporting channels, CAC has estab - lished multiple channels for receiving cybersecurity incident reports, including a dedicated cybersecurity incident reporting hotline (12387), an online reporting platform, email (12387@cert.org.cn), facsimile (010- 82992387), the “12387” WeChat Mini Programme, and the official WeChat public account of the National Computer Network Emergency Response Technical Team/Coordination Center (CNCERT). Notably, reporting an incident to CAC does not mean an organisation is exempt from reporting it to other relevant authorities who may have a need to know. In particular, where a cybersecurity incident is suspect - ed to involve potential criminal offences, the operator must also promptly report the incident to the PSB as enforcement lead; and where there are specific indus - try requirements, the operator shall also report to the competent sectoral regulators. For example, under the Measures for the Administration of the Report - ing of Cybersecurity Incidents in the Business Fields of the PBOC, upon the occurrence of a cybersecu - rity incident at or above the Relatively Severe level, financial institutions subject to the PBOC supervision shall submit a brief report within one hour and then a detailed report within 24 hours, and within ten work - ing days of the incident disposition, submit a post- incident investigation and summary report. Further, for Severe and above-level incidents, financial institutions shall submit progress reports every two hours until the incident is resolved. In addition to reporting the cybersecurity incident to competent authorities, network operators are also required to notify the affected individuals of the inci - dent. Such notification may be exempted if the net - work operator concerned can demonstrate that it has adopted effective measures to prevent or mitigate the resulting harm. Having said that, if competent authori - ties believe that the harm may not be prevented or mitigated otherwise, they may still require the network operator concerned to notify the individual.
80 CHAMBERS.COM
Powered by FlippingBook